Global CISO Insights 2026:
Identity security in the age of AI
Identity security in the age of AI
AI agents have created a governance crisis at the heart of enterprise security—and identity infrastructure is both the problem and the solution, according to a global survey of more than 300 CISOs and security executives.
Despite near-universal anxiety about AI-driven threats, fewer than half of CISOs we surveyed can confidently say they know where their agents are, what those agents can access, or what actions they're authorized to take. Governance is fragmented: Organizations are applying human identity policies to non-human agents, relying on shared credentials with broad permissions, and managing agent access on an ad hoc basis. This disconnected approach leaves blind spots across the agentic enterprise.
Boardroom misalignment is compounding the problem. According to our research, just 31% of CISOs feel fully aligned with their C-suite and board on acceptable AI risk, and less than half say their board sees AI security as a business enabler rather than a compliance checkbox. Without that alignment, CISOs struggle to secure the support responsible AI adoption requires.
The data makes it clear that you can’t secure what you can’t see, and you can’t govern what you haven't given an identity to. The good news: When organizations invest in maturing their AI identity governance, they experience less shadow AI, worry less about breaches, and contain rogue agents faster.
The clearest path forward starts with three questions: Where are my agents? What can they connect to? What can they do? Answering them is the blueprint for a secure agentic enterprise. In this report, we’ll help you benchmark your AI security against other organizations and provide actionable tips for safe, scalable AI adoption.
We surveyed 306 CISOs, heads of cybersecurity, and other security executives whose roles include either leading the organization’s information security policies or overseeing incident response and managing cybersecurity risks across the organization.
AI access sprawl is on everyone’s mind: 81% of CISOs are concerned about excessive AI access.
Agents are moving faster than security: Fewer than half of CISOs are confident they can identify all AI agents in their environment (47%), centrally control what those agents can access (46%), or authorize what individual agents can do (45%).
Many organizations are using broad rather than fine-grained AI controls: 21% of organizations use shared credentials or broad-permission service accounts to govern AI agent access.
C-suite and board alignment needs improvement: Only 31% of CISOs feel fully aligned with their C-suite and board on acceptable AI risk levels. In the US, that number falls to just 12%.
Security leaders live by the mantra that you can’t protect what you can’t see. For many organizations, the fear of shadow IT continues to plague their security teams as new apps are introduced to their stack. This visibility gap has only worsened with a flood of AI agents being introduced across apps or built in-house by their own teams.
As the foundation of our survey, we asked CISOs to rate the following statements from strongly agree to strongly disagree:
I know where my agents are
I know what my agents can connect to
I know what my agents can do
Less than half of CISOs feel confident they can identify all of the agents in their environment (47%), control what their agents interact with (46%), or authorize individual tool calls using context and intent clues (45%). The percentage drops below 30% if we only look at those who responded with “strongly agree.” This lack of confidence is pointing these leaders toward building or uncovering new solutions as quickly as possible.
can control what agents access
can authorize what agents do
France ranks last in oversight confidence. Despite high belief and anxiety that employees are using shadow AI (88% report at least some unsanctioned AI usage), French organizations rely on passive remediation: Nearly 24% only notify users and rely on policy compliance when shadow AI is found, making them uniquely exposed.
Interestingly, the research reveals a visibility vs. security paradox, where visibility alone doesn’t provide peace of mind. Even among CISOs who are fully confident they know where their AI agents are, roughly 80% remain highly concerned about excessive access and permissions. Knowing an agent's location or connections modestly tempers, but never eliminates, the worry of a breach.
"AI systems move fast, but that speed only works if you have control over the sensitive data flowing through them. Knowing what's going in, how it's being processed, and what's coming out isn't optional anymore—it's the foundation of trust in these systems."
The majority of security leaders aren’t feeling especially confident in securing their agents today, but not all companies (or regions) are at the same point in their journeys. Leaders were asked to rank their agentic identity and access governance by maturity:
Reactive: “We are just beginning to discover AI usage and do not yet have formalized identity policies or controls for AI agents.”
Developing: “We have basic policies in place for sanctioned AI, but lack comprehensive visibility and automated access controls.”
Defined: “We have standardized identity controls (e.g., SSO, MFA) applied to known AI tools, but struggle with shadow AI or downstream agent permissions.”
Advanced: “We have automated, real-time access controls, continuous monitoring, and dynamic governance for all human and AI identities.”
The UK is furthest along in its AI governance journey, with 36% of organizations reporting advanced, fully automated governance—the highest share of any country surveyed. That progress hasn't come from complacency: UK security leaders remain highly alert to risk, with 46% reporting they're "very concerned" about excessive AI access going unreviewed, second only to the US.
While more mature organizations worry less about AI-enabled security breaches and reactive orgs are most likely to be extremely worried (32%), many of these reactive teams are making the trade-off to move fast. Nearly two-thirds (61%) of reactive organizations prioritize innovation over security, a 13-point increase over the average across all maturities (48%).
That said, there’s a clear path to protection: The more mature your AI identity governance becomes, the less you need to worry about breaches, shadow AI, and rogue agents that can’t be stopped.
Reactive Companies
25% report extensive extensive shadow AI (vs. 13% industry average)
Advanced Companies
50% revoke agent access in minutes (vs. 26% industry average
Reactive Companies
18% can't identify or stop rogue AI at all (vs. 5% industry average)
Reactive companies report the most extensive shadow AI (25% compared with 13% across maturities) and are more likely to struggle to identify and stop rogue agents. Where advanced companies revoke access from rogue agents quickly (50% within minutes compared with 26% across the cohort), 18% of reactive companies can’t identify or stop them at all. Meanwhile, 55% of companies can revoke AI agent access within hours in the event of a breach—but even responding in hours is far too slow, as AI systems can execute harmful actions instantly.
Not a single company in the advanced tier struggles to identify and put a stop to these agents.
Security leaders are recognizing that the tools and processes built for human identity weren't designed for this moment—and they're moving quickly to catch up. To succeed in this new, complex environment, security teams are prioritizing governance as the path forward: putting identity at the center of their AI strategy so they can move to a fully automated, optimized, and secure agentic strategy. Maintaining full control over who has access to agents at any given moment was ranked as the most crucial AI security feature for securing the agentic enterprise by 29% of respondents, followed by agent discovery and credential management, each with 20%.
Japan reports the highest share of CISOs who are "extremely worried" about AI-driven breaches (29%)—more than any other market surveyed. They’re also twice as likely (12%) to report they have no consistent approach to governing agent identity compared with the global average (6%). Closing that gap will require board buy-in—but Japanese boards are among the most likely globally to treat AI security as a compliance hurdle rather than a business enabler, making it harder for CISOs to secure the investment they need.
This drive for better governance makes sense once you look at how AI identities are actually being managed today—the methods currently in place are, in many cases, still catching up to the risk. For example, one in four CISOs say they treat agents exactly as they do human identities. But current identity and security stacks were built for humans and traditional software that have predictable lifecycles and fixed execution paths. The non-deterministic nature of AI agents creates gaps that existing tools simply aren’t designed to close.
Even more worrisome, 21% of organizations use shared credentials or service accounts with broad permissions to govern AI access, and nearly the same amount (20%) leave agent management to the team that deployed them on an ad hoc basis.
“When we talk about governance, we're talking about treating those AI identities as first-class identities. So having them in your directory, having the governance process over them where they have a human manager who's responsible for what data they have access to, what scopes they can act in, or decisions they can make.”
The security leaders working to mature their AI governance policies are moving as fast as they can, knowing that any unmanaged entities pose a threat to their organizations. This fear of AI-driven breaches is especially acute among US-based CISOs, with 84% of respondents feeling extremely or very worried (compared with 57% of CISOs globally).
Outside of breaches, 81% of global security leaders are deeply concerned about excessive AI access not being properly reviewed.
“I love my teams using AI, but it’s almost like the AI tools are designed to make you want to overshare them.”
CISOs in Germany report the highest confidence in agent oversight but have some of the lowest actual governance maturity (58% developing or reactive). They’re also very concerned about AI phishing at nearly 81%, the highest single-threat signal in the study.
Digging into what's fueling this anxiety, security leaders point to a few specific threats. They cited AI-powered phishing attempts as the most concerning AI threat (61%), followed by malicious AI agents (49%), and deepfake authentication bypass (45%).
“AI-driven cyberattacks, like deepfakes and phishing attacks, are becoming increasingly sophisticated. They’re evolving to more successfully evade detection and deceive end users. Deepfakes are particularly concerning. We’re no longer just seeing deceptive videos, but full simulations with live responses in real time, which can be incredibly convincing.”
Across maturity levels and regional differences, security leaders found common ground in their biggest barriers to securing AI. A lack of visibility into AI identities is the most common barrier to security (48%), an especially prevalent challenge in the US market where 74% of respondents struggle with it.
Other factors standing in the way of AI security include budget and headcount restraints (39%) and silos between AI and security teams (33%), which make it difficult to implement the necessary changes. Canadian CISOs stood out from the group, believing their biggest barrier to securing the agentic enterprise lies in a lack of an industry standard (65%).
Over two-thirds (68%) of CISOs see at least some unsanctioned use of AI and agentic AI. With the limitations outlined above, teams are doing what they can to manage and respond to shadow AI threats wherever possible. The most common response overall when shadow AI is detected is to block access (35%) or bring the tool under governance and apply access controls (29%) with whatever solutions the team has available.
Executive leaders may recognize that identity is core to AI security, but there’s still a substantial gap between recognition of a strategy and complete alignment on its execution. Less than a third (31%) of CISOs feel they’re fully aligned with their C-suite and board on acceptable levels of AI-related risk. US-based leaders feel the least aligned of the cohort, with only 12% stating they feel fully aligned, an unsurprising finding given their outsized concern about breaches.
US organizations show the highest breach anxiety (84%) and high concern over overprivileged agents (65%), but they’re better positioned for success because a majority of their boards (54%) see security as a business enabler.
CISOs have been hard at work convincing their boards and C-suite executives that security is a business enabler rather than an innovation blocker, but in the age of AI, it’s become even more difficult to make that case. Less than half of CISOs (46%) feel their boards view AI security as a business enabler today.
Less than half of CISOs feel their boards view AI security as a business enabler today.
However, this friction varies significantly by region. Boards in the US and France are the most likely to view AI security as a business enabler, making them more open to investment. German and Japanese organizations, however, are the most likely to view AI security merely as a compliance or regulatory hurdle. This lack of executive understanding creates a top-down disconnect that leaves AI identity security under-resourced.
It’s up to CISOs to make it clear they’re a business team player. This advocacy may be the deciding factor between a secure agentic enterprise and one that’s stuck in a reactive state.
"Are you clearly a business team player? Yes, you're there for reducing risk and securing the organization. But are there things that if you do well, you can actually enable the organization to go fast? Partnering with the business is so crucial in my opinion."
Companies around the world see the risks associated with agentic AI but can't control it yet. Almost every security leader is worried about AI agents, but very few feel equipped to manage what those agents are doing. The majority of security leaders are reevaluating their tools and processes to match a new type of threat while still helping the business move at AI speeds. Here’s how you can too.
You can't govern what you can't see. Prioritize discovery as the foundation of your strategy by mapping where agents operate, what they can connect to, and what they can do. The blueprint for the secure agentic enterprise offers a practical framework for standing up this kind of governance model.
Governing AI agents through shared credentials or broad-permission service accounts is a legacy human-identity habit that creates unnecessary blast radius when an agent is compromised. Treat every AI agent as a first-class identity with its own lifecycle, scoped permissions, and access policy, rather than bolting agents onto existing human identity and access management frameworks.
Blocking access when shadow AI is detected isn't a scalable strategy on its own because it drives usage further underground rather than solving the underlying demand. Build a repeatable process to evaluate, onboard, and govern new AI tools quickly, so sanctioned, secure options can compete with the speed employees want. Consider identity solutions tailored to managing AI agents, such as Okta for AI Agents, to reduce shadow AI sprawl from day one.
Proactively bring data-backed risk benchmarks to leadership conversations, and frame identity controls as what enables the business to move fast, not what slows it down. Use your organization's governance maturity as the business case for further investment, and lean on external resources like this AI blueprint tool to assess your agent security architecture and identify areas for investment.
This report is based on a global survey of 306 chief information security officers (CISOs), heads of cybersecurity, and other senior security executives. The research was conducted to understand the top challenges, priorities, and perspectives related to AI agents and identity security across the enterprise.
To ensure a comprehensive global view, the survey captured insights across six major markets: the UK (33%), Japan (24.8%), the US (14.1%), France (11.1%), Canada (8.5%), and Germany (8.5%).
To maintain the executive-level integrity of the data, rigorous screening was applied to respondent demographics. All non-CISO participants were required to confirm that their roles explicitly included either leading their organization’s information security policies or overseeing incident response and managing cybersecurity risks across the organization.
The survey data was finalized in June 2026 in partnership with the research firm Apprize360 Intelligence.